Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories

2026-04-21 Trend Micro

https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html

Thumbnail for Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories

Trend Micro found Void Dokkaebi, also tracked as Famous Chollima, turning fake recruiter interviews into a worm-like supply chain campaign against software developers. Victims are lured into cloning repositories that abuse VS Code folder-open tasks, and compromised machines are then used to inject obfuscated JavaScript into configuration and entry-point files that execute during normal Node.js build, linting, or bundling activity. The actor rewrites Git history with backdated force-pushes and preserved commit metadata to hide tampering, with more than 750 infected repositories, over 500 malicious VS Code task configurations, and 101 commit-tampering tool instances observed in March 2026. The campaign delivered a DEV#POPPER RAT variant and staged payloads through blockchain infrastructure including Tron, Aptos, and Binance Smart Chain, making takedown harder. The activity matters because a single compromised developer account can seed organizational and open-source repositories, exposing contributors, forks, and downstream projects through trusted development workflows.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 198.105.127.210 2026-03-05 2026-06-12
IPv4 23.27.202.27 2025-10-20 2026-06-12
DOMAIN api.trongrid.io 2025-10-27 2026-05-31
DOMAIN fullnode.mainnet.aptoslabs.com 2025-10-27 2026-05-31
IPv4 154.91.0.196 2026-04-21 2026-04-21
IPv4 83.168.68.219 2026-04-21 2026-04-21
IPv4 23.27.120.142 2025-10-20 2026-04-21
IPv4 85.239.62.36 2025-10-20 2026-04-21
IPv4 23.27.20.143 2025-10-20 2026-04-21
IPv4 136.0.9.8 2025-10-20 2026-04-21
IPv4 166.88.4.2 2025-10-20 2026-04-21

Related Actors

Related Reports

« Back